Getting Data In

Splunk Datamodel Endpoint Processes.process_name: How do we fix the regex to only show process name?

SplunkUserD
Engager

We are having issues with our Splunk datamodel Endpoint Processes.process_name. The current value for Process.process_name is...

case(isnotnull(process) AND parent_process!="",replace(process,".*\\\\(.*)","\1"),1=1,"unknown")

The regex pulls correct and invalid results as follows...

Correct:

lsass.exe
NmService.exe
Microsoft.IdentityServer.ServiceHost.exe

Incorrect:

AppxData.csv"
BackgroundTaskHost.exe" -ServerName:BackgroundTaskHost.WebAccountProvider
RuntimeBroker.exe -Embedding

The correct results show the actual process name while the incorrect ones may not show the process name or shows the process name with an extra quotation mark or command line arguments.

How do we fix the regex to only show process name?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...